SSO and API gateway2023Backend engineer4 months
Identity Gateway
Single sign-on across a suite of enterprise apps with an OIDC gateway, short-lived tokens and centralised session revocation.
- Spring Security
- OAuth2 / OIDC
- Redis
- Kubernetes
5 to 1
logins per employee
<60s
global access revocation
The problem
Each application stored its own passwords. Off-boarding an employee meant touching five systems, and audits failed.
Constraints
- Integrate with the client's Active Directory
- Revoke access everywhere within a minute
Architecture
Apps
Web apps
Mobile
Gateway
OIDC provider
Token relay
Identity
Active Directory
Session store
Key decisions
Decision 01
Short access tokens, server-side refresh
Access tokens live 5 minutes and refresh tokens never reach the browser, so revocation is a single Redis delete.
Trade-off: More refresh traffic through the gateway.
In the code
gateway/src/main/java/SecurityConfig.java
1@Bean2SecurityFilterChain api(HttpSecurity http) throws Exception {3 return http4 .authorizeHttpRequests(auth -> auth5 .requestMatchers("/actuator/health").permitAll()6 .anyRequest().authenticated())7 .oauth2ResourceServer(rs -> rs.jwt(jwt -> jwt8 .jwtAuthenticationConverter(new RoleConverter())))9 .sessionManagement(s -> s.sessionCreationPolicy(STATELESS))10 .build();11}What I learned
- Security work lands when it removes steps for users, not when it adds them.